DocumentCode
3477956
Title
IMS Threat and Attack Surface Analysis Using Common Vulnerability Scoring System
Author
Petäjäsoja, Sami ; Kortti, Heikki ; Takanen, Ari ; Tirilä, Juha-Matti
Author_Institution
Codenomicon Ltd., Oulu, Finland
fYear
2011
fDate
18-22 July 2011
Firstpage
68
Lastpage
73
Abstract
For the purposes of this study, IMS specifications and public sources were analyzed using the general attack surface analysis methodology. These findings were verified and augmented by active scanning and passive analysis of the available real-world IMS test setups that were investigated during the project. As various tests and security probes were performed against the test setups, the system behaviour was analyzed for previously undetermined interactions and transient attack surfaces. After the IMS attack vectors had been identified, the Common Vulnerability Scoring System version 2 (CVSSv2) Base Scores were used to prioritize the IMS attack surface interfaces. CVSS is an industry standard for classifying vulnerabilities. It must be noted however that the idea of applying CVSS scoring to an a priori comparison of vulnerability categories and potential attack surfaces is original research by the authors of this study.
Keywords
IP networks; computer network security; multimedia systems; IMS attack surface analysis; IMS attack surface interfaces; IMS attack vectors; IMS specifications; IMS threat; IP multimedia subsystem; active scanning; common vulnerability scoring system version 2 base scores; general attack surface analysis methodology; passive analysis; public sources; Authentication; Availability; Complexity theory; Measurement; Protocols; Surface treatment; attack surface analysis; next generation networks; security; threat analysis;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Software and Applications Conference Workshops (COMPSACW), 2011 IEEE 35th Annual
Conference_Location
Munich
Print_ISBN
978-1-4577-0980-7
Electronic_ISBN
978-0-7695-4459-5
Type
conf
DOI
10.1109/COMPSACW.2011.22
Filename
6032214
Link To Document